Privacy Policy
This Privacy Policy describes how waitlist-kit ("we," "us," or "our"), operated by Cole, describes our practices regarding the collection, use, and disclosure of personal information when you use our service at waitlist-kit.bycole.dev (the "Service").
waitlist-kit is an embeddable waitlist widget that enables businesses ("Customers") to collect contact information from their users ("End Users"). This policy applies to both Customers who use our platform and End Users whose information is collected through our Customers' websites.
1. Information We Collect
1.1 Information Collected from Customers (Account Holders)
When you create a waitlist-kit account or use our dashboard, we may collect:
- Account information: Email address and any credentials used to access the dashboard
- API keys: Generated for widget integration
- Usage data: How you interact with our dashboard, API usage statistics, and widget configuration settings
1.2 Information Collected from End Users (via the Widget)
When an End User submits information through a waitlist-kit widget embedded on a Customer's website, we collect and process the following on behalf of the Customer:
- Phone numbers: Stored in E.164 international format
- Email addresses
- Country codes: Derived from phone number input or user selection
- Referral codes: If the End User was referred through a referral link
- IP addresses: Collected automatically through server logs
- Device and browser information: User agent string, screen resolution, and similar technical data
- Timestamp data: Date and time of waitlist signup
1.3 Information Collected Automatically
When you visit our website, we automatically collect:
- Log data: IP address, browser type, operating system, referring URLs, pages viewed, and access timestamps
- Analytics data: We use Google Analytics on our conversion tracking page to understand how visitors interact with our site. Google Analytics may set cookies on your browser. See Section 7 for more details.
2. How We Use Your Information
2.1 Customer Data
We use Customer data to:
- Provide, maintain, and improve the Service
- Authenticate access to the dashboard and API
- Communicate with you about your account and service-related matters
- Monitor and analyze usage patterns to improve our platform
- Comply with legal obligations
2.2 End User Data
We process End User data on behalf of our Customers to:
- Store and organize waitlist entries
- Enable Customers to export their waitlist data (e.g., CSV export)
- Provide analytics and statistics about waitlist performance to Customers
- Operate and maintain the technical infrastructure of the Service
We do not use End User data for our own marketing purposes. We do not sell End User data. End User data belongs to the Customer, and we process it solely as a data processor on the Customer's behalf.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, our legal bases for processing personal data are:
- Contractual necessity: Processing necessary to perform our contract with Customers
- Legitimate interests: Processing necessary for our legitimate interests (improving the Service, ensuring security)
- Consent: Where you have given explicit consent (e.g., submitting your information through a waitlist widget)
- Legal obligation: Processing necessary to comply with applicable laws
For End User data, our Customers are the data controllers and are responsible for establishing their own legal basis for collecting End User data. waitlist-kit acts as a data processor.
4. Data Sharing and Third Parties
We do not sell, rent, or trade personal information to third parties for their marketing purposes.
4.1 Infrastructure and Service Providers
- Vercel: Our hosting provider. Privacy policy
- Turso (Fly.io): Our database provider. Privacy policy
- Google Analytics: Used on our conversion tracking page. Privacy policy
4.2 Customers
End User data is made available to the Customer on whose website the widget is embedded. Customers can view, manage, and export their waitlist data through the dashboard.
4.3 Legal and Compliance
We may disclose personal information if required by law, or in response to valid legal process, or to protect our rights, privacy, safety, or property.
4.4 Business Transfers
If waitlist-kit is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will provide notice before personal information becomes subject to a different privacy policy.
5. Data Retention
- Customer data: Retained for as long as your account is active. Deleted or anonymized within 90 days of account closure.
- End User data: Retained for as long as the Customer's account is active. Customers may request deletion at any time. Deleted within 90 days of account termination.
- Log data: Retained for up to 12 months for security, debugging, and operational purposes.
6. Data Security
We implement reasonable technical and organizational measures to protect personal information, including:
- Encryption in transit: All data transmitted is encrypted using TLS/HTTPS
- Access controls: API key-based authentication; restricted access to production systems
- Infrastructure security: Our hosting and database providers maintain industry-standard security practices
- Data minimization: We collect only the data necessary to provide the Service
No method of electronic storage or transmission is 100% secure. While we strive to protect personal information, we cannot guarantee absolute security.
7. Cookies and Tracking Technologies
Our website: Uses Google Analytics cookies on the conversion tracking page. You can opt out using the Google Analytics Opt-out Browser Add-on.
The widget: Does not set cookies on End Users' browsers. The widget communicates with our API via standard HTTPS requests.
You can control cookies through your browser settings.
8. International Data Transfers
waitlist-kit is operated from the United States. If you are located outside the United States, your personal information will be transferred to and processed in the United States.
For transfers from the EEA, UK, or Switzerland, we rely on the EU-U.S. Data Privacy Framework, Standard Contractual Clauses (SCCs), and our sub-processors' own transfer mechanisms.
9. Your Privacy Rights
9.1 All Users
Regardless of your location, you may request access, correction, or deletion of your personal information.
9.2 EEA, UK, and Swiss Residents (GDPR)
You have additional rights including: right of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent.
For End Users: Please first contact the Customer (the website where you submitted your information). If you need further assistance, contact us directly.
9.3 California Residents (CCPA/CPRA)
You have the right to know, delete, correct, and opt out. We do not sell personal information.
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Email, phone number, IP address | Yes |
| Internet activity | Browsing history, site interactions | Yes |
| Geolocation data | Country code (approximate) | Yes |
To exercise your rights, contact us at contact@bycole.dev. We will respond within 45 days.
10. SMS and Phone Number Disclosures (TCPA)
waitlist-kit collects phone numbers on behalf of Customers. We do not send SMS messages, marketing texts, or automated calls to End Users.
Customers who use phone numbers for SMS communications must comply with all applicable laws, including the TCPA, and must obtain appropriate consent.
To have your phone number removed, contact the Customer directly or email us at contact@bycole.dev.
11. Children's Privacy
waitlist-kit is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at contact@bycole.dev.
12. Do Not Track
We do not currently respond to Do Not Track (DNT) signals as there is no accepted standard for how to respond to them.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will update the "Last Updated" date and post the updated policy on our website. For material changes affecting Customers, we will notify via email or dashboard notification.
14. Contact Us
waitlist-kit
Operated by Cole
Email: contact@bycole.dev
Website: waitlist-kit.bycole.dev